'Zombie Card' Attack Brings Expired Visa Contactless Cards Back to Life
UMass Amherst researchers show how to rewrite the expiry date a payment terminal sees, letting dead cards buy real goods.

Key points
- Researchers at the University of Massachusetts Amherst built an attack, dubbed Zombie Card, that lets expired Visa contactless cards make real purchases in shops.
- The trick rewrites the expiration date that a payment terminal reads over the short-range wireless link used for tap-to-pay, without cracking any of the card's cryptography.
- The attack needs brief physical access to the target card, so it is not a remote hack of the payment network itself.
- Visa's contactless standard, not the individual card's chip, is where the weakness sits, meaning any bank issuing on that standard is exposed until Visa changes how expiry is checked.
- No customer-side patch exists yet; shoppers cannot fix this themselves, but they can keep expired cards out of wallets and destroyed.
Academics have found a way to make a dead credit card spend money again.
A team at the University of Massachusetts Amherst has demonstrated an attack they call Zombie Card, which revives expired Visa contactless cards and uses them for genuine in-store purchases. The work was first reported by The Hacker News.
The method does not break the card's cryptography, meaning it does not defeat the mathematical locks that normally protect card data. Instead, it targets a simpler thing: the expiration date that the shop's payment terminal reads from the card over NFC (near-field communication, the short-range wireless link used for tap-to-pay).
By rewriting the date the terminal sees, the researchers convinced point-of-sale devices that a long-dead card was still valid. The card then completed a normal contactless payment.
How does the attack actually work?
The researchers sit in the middle of the tap. When a shopper taps a Visa contactless card on a terminal, the two devices exchange a short conversation over NFC. Inside that conversation is the card's expiry date, sent in a field the terminal trusts without a separate cryptographic check.
The UMass team showed that this field can be altered on the fly. The rest of the transaction, including the parts that are cryptographically signed, still validates. The terminal sees a card that looks in-date, and approves the sale.
Crucially, the flaw is in how Visa's contactless specification handles the expiry field, not in any single bank's card. That is why the researchers describe it as a protocol-level issue.
What does an attacker need?
They need the physical card, at least briefly. Zombie Card is not a way to clone cards from across a room or drain accounts over the internet. The researchers describe a scenario where a criminal gets hold of an expired card (from a bin, a stolen wallet, or a discarded envelope) and uses it with their rig at a checkout.
That limits the scale. But it also means every expired Visa card sitting in a drawer is, in theory, still spendable.
Should ordinary shoppers worry?
Probably not day to day, but destroy expired cards properly. Cut through the chip and the magnetic stripe before you throw the card away. Do not assume that an expiry date on the front of the card means the chip inside has stopped working.
If you spot charges on a closed or expired card account, report them to your bank the same way you would any fraud. Under UK and EU rules, unauthorised card transactions are generally refundable.
| Detail | What the researchers say |
|---|---|
| Attack name | Zombie Card |
| Discovered by | University of Massachusetts Amherst |
| Card brand affected | Visa contactless |
| Access needed | Physical possession of the expired card |
| Cryptography broken? | No |
| Fix location | Visa's contactless specification |
Where does the fix have to come from?
From Visa, and from the terminals. Because the weakness sits in how the expiry date is trusted during a tap, individual banks cannot patch it alone by reissuing plastic. Visa would need to change the specification so terminals verify the expiry against a signed value, and terminal vendors would need to roll that change out to millions of devices in shops around the world.
That is a slow process. Until it happens, the safest assumption is simple: an expired Visa contactless card is not as dead as it looks.



